{"id":842,"date":"2026-08-19T09:22:11","date_gmt":"2026-08-19T03:52:11","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=842"},"modified":"2026-08-19T09:22:46","modified_gmt":"2026-08-19T03:52:46","slug":"certighost-cve-2026-54121-adcs-domain-takeover","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/","title":{"rendered":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide"},"content":{"rendered":"<p>A newly released proof-of-concept exploit is turning heads across enterprise security teams \u2014 and for good reason. Dubbed Certighost and tracked as CVE-2026-54121, the vulnerability targets Active Directory Certificate Services (AD CS), the PKI backbone that most Windows-based enterprises rely on for certificate-based authentication.<\/p>\n<p>Microsoft patched the flaw in its July 2026 Patch Tuesday release. But the story didn&#8217;t end there. Ten days later, researchers publicly dropped a fully functional PoC, collapsing the gap between &#8220;theoretical risk&#8221; and &#8220;weaponized attack chain.&#8221;<\/p>\n<p>What makes Certighost dangerous isn&#8217;t just the CVSS 8.8 score \u2014 it&#8217;s the blast radius. A single authenticated, low-privileged domain account is enough to manipulate machine-account attributes, forge a certificate impersonating a domain controller, and pivot straight into a full domain compromise via DCSync. For any organization running AD CS, this is no longer a hypothetical exercise in &#8220;what could happen.&#8221; It&#8217;s a live, public roadmap for what already can.<\/p>\n<h2>The Exploit Chain, Step by Step<\/h2>\n<p>The root cause of Certighost lies in a fallback lookup process inside AD CS enrollment, which researchers have labeled the &#8220;chase&#8221; mechanism. When the Certification Authority (CA) processes a certificate request, it sometimes performs a secondary directory lookup to resolve the requester&#8217;s identity \u2014 and this lookup can be redirected to an attacker-controlled host.<\/p>\n<p>The exploit chain works like this:<\/p>\n<ul>\n<li><strong>Machine account creation<\/strong> \u2013 A standard domain user leverages the default ms-DS-MachineAccountQuota value of 10, which permits any authenticated user to create up to 10 machine accounts with zero elevated privileges required.<\/li>\n<li><strong>Rogue listener setup<\/strong> \u2013 The attacker stands up fake SMB\/LSA and LDAP services to intercept the CA&#8217;s chase lookup.<\/li>\n<li><strong>Identity coercion<\/strong> \u2013 When the CA reaches out during enrollment, it queries the attacker&#8217;s rogue services and receives falsified directory data \u2014 specifically the objectSid and dNSHostName of the targeted domain controller.<\/li>\n<li><strong>Certificate issuance<\/strong> \u2013 The CA, trusting this fabricated response, issues a certificate bound to the domain controller&#8217;s identity rather than the attacker&#8217;s actual machine account.<\/li>\n<li><strong>PKINIT authentication<\/strong> \u2013 The forged certificate is used to authenticate via PKINIT, yielding valid Kerberos credentials for the domain controller.<\/li>\n<li><strong>Privilege escalation<\/strong> \u2013 Because domain controller accounts hold directory replication rights, the attacker runs DCSync to extract the krbtgt account&#8217;s credentials \u2014 effectively obtaining the keys to forge unlimited domain access via Golden Tickets.<\/li>\n<\/ul>\n<p>One of the most effective mitigations is to set the Active Directory <code>ms-DS-MachineAccountQuota<\/code> attribute to <code>0<\/code> if your organization does not require standard users to create computer accounts. This hardening measure prevents unprivileged users from creating new machine accounts, immediately breaking the first step of this exploit chain.<\/p>\n<p>The entire chain requires only network reachability and a standard domain account \u2014 no administrative rights, no user interaction, and no prior foothold beyond basic domain membership.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-Is-Workforce-Identity-A-Complete-Guide-for-IT-Teams.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What Is Workforce Identity? A Complete Guide for IT Teams<\/h4><p>Workforce Identity helps IT teams secure users, devices, and enterprise access across today's hybrid workplaces.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-workforce-identity-a-complete-guide-for-it-teams\/\" aria-label=\"What Is Workforce Identity? A Complete Guide for IT Teams\"><\/a><\/div><\/div><\/div><\/p>\n<h2>The Hexnode Solution<\/h2>\n<p>Certighost is fundamentally a patching and identity-hygiene problem \u2014 which means the right tooling can compress both detection time and exposure window significantly.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a><\/strong> applies behavioral analytics across managed Windows endpoints to flag anomalous activity patterns \u2014 including credential-harvesting techniques and unusual process behavior \u2014 that can surface early indicators of an in-progress attack chain like Certighost&#8217;s, such as suspicious credential access attempts or signs of privilege escalation on a domain-joined machine.<\/li>\n<li><strong><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a><\/strong> enforces automated, CVE\/KB-criteria-based patch deployment across Windows endpoints and privileged administrator workstations, helping organizations keep the managed devices used to administer Active Directory and AD CS environments up to date with applicable security updates. Real-time compliance reporting gives IT teams audit-ready visibility into which managed Windows devices have applied the relevant July 2026 security updates and which remain exposed.<\/li>\n<li><strong><a href=\"https:\/\/www.hexnode.com\/idp\/\" rel=\"noopener\">Hexnode IdP<\/a><\/strong> adds a critical containment layer: its compliance-based access control blocks login attempts from devices flagged as unenrolled or non-compliant within Hexnode UEM, so even if credentials are compromised via a Certighost-style attack, access from an untrusted or non-compliant endpoint can be denied outright. Continuous device-posture verification means access can be revoked mid-session the moment risk conditions change \u2014 a meaningful check against attackers attempting to leverage forged domain-controller credentials from outside the managed fleet.<\/li>\n<\/ul>\n<p>Together, these capabilities don&#8217;t eliminate the need to patch \u2014 nothing does \u2014 but they shrink the practical window an attacker has to operationalize a PoC like Certighost inside your environment.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-IdP-Solution-brief\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-IdP-Solution-brief-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-IdP-Solution-brief\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode IdP Solution Brief\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Check out this solution brief for a quick glance into Hexnode IdP's capabilities.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/datasheets\/hexnode-idp-solution-brief\/'>\n                            Get the Datasheet\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Conclusion<\/h2>\n<p>Certighost is a reminder that identity infrastructure is attack surface \u2014 not a background utility that quietly issues certificates and stays out of the security conversation. When a Certification Authority can be coerced into vouching for the wrong identity, every downstream trust decision built on that certificate becomes suspect.<\/p>\n<p>For enterprises running AD CS, the response can&#8217;t stop at applying the July 2026 patch, though that remains the non-negotiable first step. Security teams should also:<\/p>\n<ul>\n<li><strong>Review Certification Authority behavior<\/strong> \u2013 Audit enrollment configurations and chase-related lookup paths for exposure, not just patch status.<\/li>\n<li><strong>Monitor Kerberos and DCSync indicators<\/strong> \u2013 Treat unusual PKINIT authentication attempts and replication requests as high-priority signals, not background noise.<\/li>\n<li><strong>Reclassify certificate abuse as a domain-compromise risk<\/strong> \u2013 Certificate misuse is no longer a niche PKI concern; it&#8217;s a direct path to full Active Directory takeover.<\/li>\n<li><strong>Restrict machine account creation<\/strong> \u2013 Set the Active Directory <code>ms-DS-MachineAccountQuota<\/code> attribute to <code>0<\/code> so non-administrator users cannot create rogue computer accounts. This immediately blocks the first step of the Certighost exploit chain while aligning with Active Directory hardening best practices.<\/li>\n<\/ul>\n<p>The organizations that treat AD CS with the same scrutiny as their domain controllers \u2014 rather than as a &#8220;set it and forget it&#8221; service \u2014 will be the ones positioned to catch the next Certighost before it becomes a headline.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try Hexnode free for 14 days<\/h5><p>Secure your identity infrastructure before attackers do \u2014 try Hexnode free and see the difference.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A newly released proof-of-concept exploit is turning heads across enterprise security teams \u2014 and for&#8230;<\/p>\n","protected":false},"author":8,"featured_media":843,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,16],"class_list":["post-842","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-windows","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide<\/title>\n<meta name=\"description\" content=\"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide\" \/>\n<meta property=\"og:description\" content=\"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T03:52:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T03:52:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide\",\"datePublished\":\"2026-08-19T03:52:11+00:00\",\"dateModified\":\"2026-08-19T03:52:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/\"},\"wordCount\":917,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Certighost.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/\",\"name\":\"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Certighost.webp?format=webp\",\"datePublished\":\"2026-08-19T03:52:11+00:00\",\"dateModified\":\"2026-08-19T03:52:46+00:00\",\"description\":\"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Certighost.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Certighost.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"Certighost\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/certighost-cve-2026-54121-adcs-domain-takeover\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide","description":"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/","og_locale":"en_US","og_type":"article","og_title":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide","og_description":"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T03:52:11+00:00","article_modified_time":"2026-08-19T03:52:46+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide","datePublished":"2026-08-19T03:52:11+00:00","dateModified":"2026-08-19T03:52:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/"},"wordCount":917,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp","articleSection":["Identity Abuse","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/","url":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/","name":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp","datePublished":"2026-08-19T03:52:11+00:00","dateModified":"2026-08-19T03:52:46+00:00","description":"A Certighost PoC for CVE-2026-54121 can enable AD CS domain takeover. Learn patching, identity, and XDR defense steps.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Certighost.webp?format=webp","width":1024,"height":535,"caption":"Certighost"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/certighost-cve-2026-54121-adcs-domain-takeover\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Certighost CVE-2026-54121 PoC Released: AD CS Domain Takeover Defense Guide"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=842"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/842\/revisions"}],"predecessor-version":[{"id":847,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/842\/revisions\/847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/843"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}